PT-2026-57217 · Grav · Grav

CVE-2026-53653

·

Published

2026-07-10

·

Updated

2026-08-14

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.7.53 Grav versions prior to 2.0.0-rc.8
Description An unauthenticated visitor can cause server memory and CPU exhaustion by requesting image derivatives with oversized dimensions. This occurs through URL query image actions, such as forceResize in the Grav::fallbackUrl function, which passes request parameters to ImageMedium magic actions without enforcing a dimension or pixel ceiling.
Recommendations Update Grav to version 1.7.53 or later. Update Grav to version 2.0.0-rc.8 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53653
GHSA-4X9G-VW65-VVF9

Affected Products

Grav